PROJECT 02 / ASPA PREVIEW

What ASPA
would drop today

RIPE RIS Liverpki-clientUpdated every minute

ASPA lets a network publish who its upstream providers are. Routers that enforce it reject paths that could only exist through a route leak. This page checks the public BGP stream against every published ASPA object and shows what enforcement would remove right now.

Live state

Loading Waiting for the first summary…
Prefixes seen—last 60 minutes
With an invalid path— 
With a valid path—every hop attested
Invalid routes—distinct prefix + path
ASPA objects— 
RIS collectors— 
01

Blocking attestations

Every invalid path has a gap: the climb from the origin and the descent from the observer cannot meet. Each side of that gap ends at an AS whose ASPA excludes the next hop. Either the route leaked in between, or that ASPA is incomplete. Ranked by distinct prefixes affected.

AS (attests)ExcludesPrefixesRoutesOriginsObservers
No data yet.
02

Recent invalid paths

Paths read from observer to origin. Highlighted hops are the two blocking attestations; the leak, or the missing provider, sits between them. Most recent first, at most 200.

PrefixAS pathCollectorsLast seen
No data yet.
03

Method

A / SOURCE

RIS Live

Every BGP announcement from all RIPE RIS route collectors, as it happens. Prepends are collapsed; paths with AS_SETs are counted separately.

B / VALIDATION

rpki-client

All five RIR trust anchors, refreshed every fifteen minutes over RRDP. Repositories that only offer rsync are not included.

C / ALGORITHM

Downstream check

RIS peers send full tables, so each collector is treated as a customer of its peer and paths are checked with the downstream procedure of draft-ietf-sidrops-aspa-verification.

An invalid path is evidence, not a verdict. It shows where a published attestation and observed routing disagree. Counts are distinct prefixes and routes over the last hour, so a single busy session cannot inflate them.